fa9537bcb5
fix: longer wait for sys.db, fallback to touch + userCount check
2026-07-07 16:33:49 +01:00
c42807d076
refactor: configure Zoraxy via BoltDB + config files, no API/CSRF
2026-07-07 16:19:34 +01:00
90c8c57fbe
debug: show login.html response when CSRF fetch fails
2026-07-07 16:12:30 +01:00
b1004e4514
fix: BoltDB fallback for admin creation if CSRF API fails
2026-07-07 16:12:05 +01:00
fd1fa7dbeb
fix: CSRF token — clear jar before first fetch, preserve session across calls
2026-07-07 16:08:20 +01:00
710781bc47
fix: surface admin registration result instead of swallowing it
2026-07-07 16:05:31 +01:00
b2e3086e10
fix: upload existing LE certs to Zoraxy via API after deploy
2026-07-07 15:51:25 +01:00
5f46d3c2b8
refactor: rename backup dir to /opt/backup/certificates/
2026-07-07 15:33:22 +01:00
6d87718b43
refactor: lego outputs to /opt/backup/certs/, one backup directory
2026-07-07 15:27:30 +01:00
c7d25c0107
fix: fallback to lego SAN cert directory if backup missing
2026-07-07 15:24:03 +01:00
5f168d21f1
feat: replace autocert with lego CLI for reliable LE cert issuance
2026-07-07 15:05:41 +01:00
02bab22a5d
fix: build tool from script directory (correct go.mod context)
2026-07-07 14:57:30 +01:00
533b6f4137
fix: full service teardown (stop+disable+remove) + port 80 wait
2026-07-07 14:53:00 +01:00
63099703a1
fix: stop Zoraxy before running tool to free port 80 for ACME
2026-07-07 14:44:13 +01:00
360112c7b7
fix: remove old zoraxy container before deploying
2026-07-07 14:33:28 +01:00
2e7a0e3645
refactor: /opt/backup/ vault for .env + certs, clean destroy flow
2026-07-07 14:30:48 +01:00
b0a3cd3206
fix: tool only manages backup, preservation handles cert deployment
2026-07-07 14:14:36 +01:00
25c0e7b9b7
docs: remove --destroy blocker — tool handles cert backup/restore
2026-07-07 12:57:58 +01:00
2398bdce83
feat: nextwks-tool for LE + DB + Zoraxy Auth
2026-07-07 12:53:57 +01:00
d73b67614e
fix: proxy www through binary for ACME challenge support
2026-07-07 12:22:11 +01:00
038d923a11
fix: include www in LE cert auto-generation loop
2026-07-07 12:19:17 +01:00
4e50bf15dd
fix: www files go to html/ subdirectory (Zoraxy static root)
2026-07-07 12:13:06 +01:00
ddef538795
feat: www landing page with component listing
2026-07-07 12:09:25 +01:00
7b3942658d
docs: add 5s safety warning before --destroy
2026-07-07 12:06:12 +01:00
79bf23618d
fix: proper Zoraxy CSRF/session handling (login.html + cookie jar)
2026-07-07 12:02:59 +01:00
d0f9854084
fix: bypass global TLS for dns subdomain (HTTP without redirect)
2026-07-07 11:04:12 +01:00
ccd362a964
fix: hoist COOKIE_JAR outside function to avoid unbound variable
2026-07-07 10:56:17 +01:00
acd9671359
fix: preserve Zoraxy certs across greenfield destroy
2026-07-07 10:52:16 +01:00
eabbcdaa2d
fix: request LE certs for all subdomains (app + dns) on greenfield
2026-07-07 10:47:38 +01:00
22471e479b
fix: unlock immutable files before destroy, timeout LE cert request
2026-07-07 10:34:36 +01:00
8ee09fb229
chore: version 0.1.0 with changelog
2026-07-07 10:29:59 +01:00
d2fa6c7365
fix: robust Zoraxy admin creation + LE automation with proper CSRF
2026-07-07 10:21:24 +01:00
47efc2e62d
fix: lock Zoraxy proxy configs with immutable flag (chattr +i)
2026-07-07 09:56:39 +01:00
4416f15797
fix: Zoraxy config expansion — use full schema with origin IP
2026-07-07 09:53:29 +01:00
f9b1b3aa7b
fix: preserve .env across greenfield destroy
2026-07-07 09:16:12 +01:00
8366164155
fix: restore dns config, Zoraxy admin, LE automation
2026-07-07 09:13:07 +01:00
49ac348694
feat: combined launcher + auth-proxy with path-based routing
2026-07-06 20:58:33 +01:00
c54c01d609
fix: write SSO redirect URL directly to BoltDB
2026-07-06 19:55:10 +01:00
9bc8310db1
fix: CSRF token handling with follow redirects and cookie jar
2026-07-06 19:04:39 +01:00
57defd7a63
feat: automated LE + ZorxAuth SSO via deploy API
2026-07-06 18:57:12 +01:00
91232a7beb
fix: dns.nextwks.eu use AuthMethod 0 (no SSO)
2026-07-06 18:12:51 +01:00
7a4328040b
feat: interactive install, .env secrets, Zoraxy admin API
2026-07-06 18:06:09 +01:00
2798485a2c
fix: Zoraxy config path (conf/proxy/), origin IP, filename
2026-07-06 16:57:34 +01:00
7fdf6692df
feat: Zoraxy proxy + launcher rewrite
2026-07-06 16:49:57 +01:00
29b9f3c159
feat(deploy): add --destroy flag and smart update modes
2026-07-06 15:36:48 +01:00
cd15d294a1
feat: subdomain router with certmagic integration
2026-07-06 15:25:21 +01:00
2d3832df0b
feat: hello world pipeline proof
2026-07-06 10:28:20 +01:00
e575b4eeb0
feat: self-signed TLS fallback on :443 + proxy as central router
...
- Add CertFile/KeyFile fields to TLSConfig (config.go)
- File-based TLS fallback: when cert_file+key_file set, ListenAndServeTLS on :443
while keeping HTTP on configured port (certmagic ACME is non-fallback path)
- deploy.sh: enable TLS by default, generate self-signed cert during deploy
- deploy.sh: change default port 8080 → 80 (reverse proxy standard)
- deploy.sh: add cert_file/key_file to config template
- proxy as central router fix (handler.go: ServeHTTP + StaticHandler methods)
2026-07-06 08:59:12 +01:00
b069cab1e3
fix(deploy): default server port to 80 (reverse proxy standard)
...
- Change config template in deploy.sh from port 8080 to port 80
- A reverse proxy must listen on port 80 for public HTTP traffic
- CAP_NET_BIND_SERVICE allows non-root binding to low ports
2026-07-06 08:54:58 +01:00
1efeb05f4f
deploy: production deploy script + path alignment to /opt/nextworkspace/
...
- Add deploy.sh: idempotent production deploy (scaffold, build, systemd, health check)
- Fix update.sh: align all paths from /opt/nextwks/ to /opt/nextworkspace/ (blueprint-compliant)
- deploy.sh safe for first-time setup and subsequent updates
- Creates full blueprint directory tree: config/, data/, logs/, src/core/
2026-07-05 18:19:33 +01:00